CVE-2026-106449
LowAdvisory
Published 7 Oct 2026In the index since 8 Oct 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.7
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 113
- of 18,053 indexed, latest versions
- Container images
- 113
- deployed by those charts
- Fix available
- 1 of 1
- affected package
yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError
Carried by container images the latest versions of 113 of 18,053 indexed charts deploy, on 113 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| lz4-javamaven | 1.10.1, 1.10.2, 1.10.4, 1.11.0+2 more | 1.11.4 | 113 |
- OSV records
- GHSA-343h-94h5-c4wr
Charts affected
113 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| pulsarquench-pulsarVerified publisher | 0.0.22 | 1 of 1See more | 118 |
| skywalkingquench-skywalkingVerified publisher | 0.0.18 | 1 of 1See more | 74 |
| streaming-stackquench-streaming-stackVerified publisher | 0.0.9 | 2 of 3See more | 259 |
| trinoquench-trinoVerified publisher | 0.0.8 | 1 of 1See more | 83 |
| wildflyquench-wildflyVerified publisher | 0.0.6 | 1 of 1See more | 72 |
| zipkinquench-zipkinVerified publisher | 0.0.5 | 1 of 1See more | 107 |
| catalog-serverradar-baseVerified publisher | 0.9.3 | 1 of 1See more | 2,835 |
| radar-gatewayradar-baseVerified publisher | 1.9.0 | 1 of 2See more | 2,719 |
| hazelcaststakaterVerified publisher | 1.0.2 | 1 of 1See more | 1,932 |
| kafkatwomartensVerified publisher | 0.2.1 | 1 of 2See more | 1,945 |
| elasticsearchwiremindVerified publisher | 8.19.1 | 1 of 1See more | 687 |
| metabasewiremindVerified publisher | 2.27.5-wiremind0 | 1 of 1See more | 1,878 |
| zipkinzipkinVerified publisher | 0.5.0 | 1 of 1See more | 1,403 |
Container images carrying it
113 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.